Privacy Policy — Group Audit for Jira
1. Who we are
Group Audit for Jira ("the app") is operated by Fabian Hönes (contact: kontakt@arbeitstyp.de). For the data the app reads inside your Jira instance we are neither a data controller nor a data processor — that data is processed entirely within your Atlassian environment and never reaches us (sections 2–4). We act as a data controller only for support correspondence you choose to send us directly (section 5).
2. What the app does with data
When a Jira administrator runs a scan, the app reads Jira configuration data through the official Jira Cloud REST API: permission schemes, notification schemes, project roles, issue security schemes, filter and dashboard sharing settings, application role groups, and the member list of the selected group (display names and active/inactive status).
This data is processed only inside your Atlassian instance and only for the moment of the scan, to display the audit report in the administrator's browser. The app has no database and no storage: results exist only in the administrator's browser session and, if the administrator chooses to export them, in a CSV file saved locally on their own device. When the page is closed, the results are gone.
3. What the app does not do
The app has no backend servers of its own, makes no network requests to any system other than your own Atlassian instance (no egress), does not modify any Jira data (read-only permission scopes only), and does not use cookies, analytics, tracking or advertising of any kind. We — the app vendor — never see, receive or store any of your data. We cannot access your Jira instance.
4. Hosting and platform
The app runs on Atlassian Forge, Atlassian's own app platform. Atlassian's processing of your data is governed by the Atlassian Privacy Policy and your agreements with Atlassian. Purchases and billing for the app are handled entirely by Atlassian through the Atlassian Marketplace; we receive aggregated sales reporting from Atlassian, not your payment data.
5. Support requests
If you contact us at kontakt@arbeitstyp.de, we use your email address and the content of your message solely to answer your request (legal basis: Art. 6(1)(f) GDPR — responding to your inquiry). Support emails are deleted once the request is resolved, unless a longer retention is legally required.
6. Your rights
Under the GDPR you have the rights of access, rectification, erasure, restriction, data portability and objection regarding personal data we process (which, per the above, is limited to support correspondence). You also have the right to lodge a complaint with a supervisory authority. For any request, contact kontakt@arbeitstyp.de.
7. Changes
If the app ever changes in a way that affects data handling, this policy will be updated before the change ships, with a new effective date.